apiVersion: v1
kind: ServiceAccount
metadata:
  name: safe-agent-updater
  namespace: d8-{{ .Chart.Name }}
  {{ include "helm_lib_module_labels" (list . (dict "app" "safe-agent-updater")) | nindent 2 }}
---
kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  name: d8:{{ .Chart.Name }}:safe-agent-updater
  {{ include "helm_lib_module_labels" (list . (dict "app" "safe-agent-updater")) | nindent 2 }}
rules:
- apiGroups:
    - ""
  resources:
    - pods
  verbs:
    - get
    - list
    - delete
- apiGroups:
  - apps
  resources:
  - daemonsets
  verbs:
  - get
  - list
---
kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  name: d8:{{ .Chart.Name }}:safe-agent-updater
  {{ include "helm_lib_module_labels" (list . (dict "app" "safe-agent-updater")) | nindent 2 }}
subjects:
  - kind: ServiceAccount
    name: safe-agent-updater
    namespace: d8-{{ .Chart.Name }}
roleRef:
  kind: ClusterRole
  name: d8:{{ .Chart.Name }}:safe-agent-updater
  apiGroup: rbac.authorization.k8s.io
